
Researcher Demonstrates How Malicious Extensions Can Hijack Browser AI Agents
Security researcher Gal Weizman of Forever Security revealed a new attack vector called 'BragJack' that allows malicious browser extensions to hijack AI assistants in Chrome, Edge, and other Chromium-based browsers. By exploiting the declarativeNetRequest system, attackers can force AI agents to perform actions without additional user clicks, potentially accessing local files, screenshots, and camera feeds. The research led to over $20,000 in bug bounties and two CVEs, with Google and Microsoft confirming patches for the identified vulnerabilities.












